<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: cobb]]></title>
    <link>http://securityratty.com/tag/cobb</link>
    <description></description>
    <pubDate>Mon, 18 Feb 2008 12:23:38 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[The Continuing .Gov Blackat SEO Campaign]]></title>
      <link>http://securityratty.com/article/20bc317bf017dd20ebd3bb5ebec5b01a</link>
      <guid>http://securityratty.com/article/20bc317bf017dd20ebd3bb5ebec5b01a</guid>
      <description><![CDATA[Just like the situation in the previous case of injecting SEO content into .gov domains , once the pages are up and running, they get actively advertised across the Web, again automatically. While...]]></description>
      <content:encoded><![CDATA[<a href="http://bp1.blogger.com/_wICHhTiQmrA/R7nzm6d7lrI/AAAAAAAABYo/vBZdtq6xIAA/s1600-h/bridger_SEO_content.jpg"><img id="BLOGGER_PHOTO_ID_5168429897239729842" style="FLOAT: left; MARGIN: 0px 10px 10px 0px; CURSOR: hand" alt="" src="http://bp1.blogger.com/_wICHhTiQmrA/R7nzm6d7lrI/AAAAAAAABYo/vBZdtq6xIAA/s200/bridger_SEO_content.jpg" border="0" /></a>Just like the situation in <a href="http://ddanchev.blogspot.com/2007/10/compromised-sites-serving-malware-and.html">the previous case</a> of <a href="http://ddanchev.blogspot.com/2007/11/p0rngov-ongoing-blackhat-seo-operation.html">injecting SEO content into .gov domains</a>, once the pages are up and running, they get actively advertised across the Web, again automatically. While <strong>bridger-mt.gov</strong> responds to <strong>72.22.69.184</strong>, the subdomain <strong>freeporn.eee.bridger-mt.gov</strong> is pointing to another netblock, in this case <strong>66.49.238.80</strong>, exactly the same approach was used in a previous such assessment that was however serving malware to its visitors. Here are some of the very latest such examples listed by directory :<br /><br />- Cobb County Government - <strong>cobbcountyga.gov/css</strong> - over 2,240 pages<br />- Benton Franklin Health District  - <strong>bfhd.wa.gov/search/templates/dark/.thumbs</strong> - 1,200 pages<br />- Bridger, Montana - <strong>freeporn.eee.bridger-mt.gov</strong> - 778 pages<br />- Mid-Region Council of Governments - <strong>mrcog-nm.gov/includes/phpmailer/language</strong> - 336 pages<br />- Michigan Senate - <strong>senate.michigan.gov/FindYourSenator/top</strong> - 26 pages<br />- Nevada City, California - <strong>nevadacityca.gov/postcards</strong> - 13 pages<br />- Brookhaven National Laboratory - <strong>pvd.chm.bnl.gov/twiki/pub/Trash/OnlinePharmacy</strong> - 12 pages<br /><br />Who's behind all of these? Checking the outgoing links and verifying the forums the advertisements got posted at could prove informative, but for instance, <strong>topsfield-ma.gov/warrant</strong> where a single blackhat SEO page was located seems to <a href="http://ddanchev.blogspot.com/2007/11/overperforming-turkish-hacktivists.html">have been hacked</a> by a <a href="http://ddanchev.blogspot.com/2007/11/mass-defacement-by-turkish-hacktivists.html">turkish defacement group</a> who left the following - "<em>RapciSeLo WaS HeRe !!! OwNz You - For AvciHack.CoM with greets given to "J0k3R  inf3RNo  ByMs-Dos  FuriOuS  SSeS  UmuT  SerSeriiii  Ov3R  YstanBLue  DeHS@ CMD  3RR0R  SaNaLBeLa  Keyser-SoZe  GoLg3  J0k3ReM  JackalTR  Albay ParS  MicroP</em>"<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=taCAhJE"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=taCAhJE" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=5UkcTdE"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=5UkcTdE" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=kuB8mre"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=kuB8mre" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=pz8ncXe"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=pz8ncXe" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=paftldE"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=paftldE" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=QsquYyE"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=QsquYyE" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=wNv87Pe"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=wNv87Pe" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/237185889" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 18 Feb 2008 12:23:38 +0000</pubDate>
      <category domain="http://securityratty.com/tag/gov">gov</category>
      <category domain="http://securityratty.com/tag/pages">pages</category>
      <category domain="http://securityratty.com/tag/gov domains">gov domains</category>
      <category domain="http://securityratty.com/tag/bridger">bridger</category>
      <category domain="http://securityratty.com/tag/gov responds">gov responds</category>
      <category domain="http://securityratty.com/tag/bridger-mt">bridger-mt</category>
      <category domain="http://securityratty.com/tag/cobb county government">cobb county government</category>
      <category domain="http://securityratty.com/tag/freeporn">freeporn</category>
      <category domain="http://securityratty.com/tag/subdomain freeporn">subdomain freeporn</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/237185889/continuing-gov-blackat-seo-campaign.html">The Continuing .Gov Blackat SEO Campaign</source>
    </item>
  </channel>
</rss>
